<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Google Workspaces on Securosis</title><link>/tags/google-workspaces/</link><description>Recent content in Google Workspaces on Securosis</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sun, 25 Jun 2023 18:25:26 -0400</lastBuildDate><atom:link href="/tags/google-workspaces/index.xml" rel="self" type="application/rss+xml"/><item><title>Leveraging AWS SSO (aka Identity Center) with Google Workspaces - version 2</title><link>/research/howto/aws-identity-center-google-v2/</link><pubDate>Sun, 25 Jun 2023 18:25:26 -0400</pubDate><guid>/research/howto/aws-identity-center-google-v2/</guid><description>&lt;blockquote&gt;
&lt;p&gt;This is a revised version of the original post &lt;a href="blog/aws-identity-center-google/"&gt;Leveraging AWS SSO (aka Identity Center) with Google Workspaces&lt;/a&gt; based on the new announcement &lt;a href="https://aws.amazon.com/about-aws/whats-new/2023/06/aws-iam-identity-center-automated-user-provisioning-google-workspace/"&gt;AWS IAM Identity Center now supports automated user provisioning from Google Workspace&lt;/a&gt; The original post is still valid, and in someways may be better, but this version has it&amp;rsquo;s own advantages.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;Setting up &lt;a href="https://aws.amazon.com/iam/identity-center/"&gt;AWS IAM Identity Center (successor to AWS Single Sign-On)&lt;/a&gt;, hereafter called AWS SSO (because I have to pay AWS for egress on this site), is an excellent service to help you get rid of IAM users and enforce identity best practices around second-factor authentication, on and off-boarding employees, and assigning the right level of access depending on job function.&lt;/p&gt;
&lt;p&gt;Companies using Google Workspaces for email and collaboration can also leverage their Google accounts to access AWS via AWS SSO. The process isn&amp;rsquo;t clearly documented, and the provisioning support isn&amp;rsquo;t integrated, so here is a post to help you set it all up.&lt;/p&gt;</description></item></channel></rss>